chore(harness-state): integration pass — docs reconciliation and proven invariant rows - #326
Conversation
|
Validation note (full workspace suite, this host): |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5d30ce5e95
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
5d30ce5 to
8ed3e23
Compare
Refinement-pass dispositionsEvery finding from the two critiques, the live smoke, the two captures, and the 20 review threads, one line each:
Validation at the new stack top: lib 410/410, agent-spec 56, invariants/doctor/status_agents/driver_expansion/claude_hooks/harness_state_teardown all green, 🤖 Generated with Claude Code |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8ed3e234bc
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
8ed3e23 to
285d1ff
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 285d1ff9f5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Fix-cycle 2 disposition — the 12 threads the bot opened against the refined commits, all adversarially verified, all CONFIRMED, none refuted:
Also landed in the same cascade (scope addition): the machine-readable |
285d1ff to
cdbabf4
Compare
|
Fix-cycle 3 disposition — 15 threads (the 9-thread wave plus 6 follow-ons), all adversarially verified, all CONFIRMED, all fixed and resolved:
Validation at the top ( |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: cdbabf4603
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
cdbabf4 to
5753670
Compare
|
Fix-cycle 4 disposition — 13 threads, all verified, all CONFIRMED, all fixed and resolved:
Self-review gate (new protocol): adversarial pass over the full cycle-4 delta against the recurring defect classes before submitting. It verified handler-before-spawn on all four wrappers and caught two bounded residuals now stated in the spec ( Validation at the top ( |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5753670178
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
5753670 to
a6cd52a
Compare
|
Fix-cycle 5 disposition — 11 threads: 9 CONFIRMED-fixed, 2 DECLINED (the wave's first refuted findings):
Self-review gate: adversarial pass over the whole cycle-5 delta (third ownership-semantics revision — the twice-bitten class). It verified the claim/refusal direction across all producers and every Writer construction site, then caught one real defect: opencode's written claim executed after Validation at the top ( |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5fcf003ba4
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
5fcf003 to
d43320c
Compare
|
Fix-cycle 7 disposition — 12 threads: 11 CONFIRMED-fixed, 1 DECLINED (third repetition of the stale pi pre-escalation claim; cited the terminal-only observer, the shared stop path, and the SIGKILL-asserting matrix):
Self-review gate (expanded classes: check-then-act across locks; error-arm terminal writes): the lock-span audit confirmed every claim is now a single locked act, and the error-arm sweep caught two more placeholder-standing arms in the same class as the reported one — pi's post-claim launch failures ( Validation at the top ( |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d43320c45f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
d43320c to
13944ab
Compare
Cycle 8 disposition — 9 threads (8 fixed, 1 declined)
Pre-submit self-review over the delta (all 12 hunt classes, subagent): verdict FIX-FIRST, all blocking findings fixed before this submit —
Validation at the tip: 449 lib tests + 3 subprocess teardown tests green ( |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 13944aba37
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| Open questions are tracked in [open-questions.md](./open-questions.md). | ||
| Draft. The envelope (`src/harness_state.rs`), all four producers, the scoped | ||
| delivery-input watcher, and the roster/Doctor exposure are implemented; the | ||
| former DELTA-005 fence is resolved and deleted, and the DQ-H1 and DQ-H6 |
There was a problem hiding this comment.
Remove the delta file before claiming it is deleted
Fresh evidence after the producer fixes is that a repo-wide search still finds docs/vrs/.delta/DELTA-005-harness-state-specified-ahead-of-full-implementation.md. That file retains all seven unchecked boxes and still states that no producers, roster exposure, or scoped watcher exist, so readers encounter an active implementation fence that directly contradicts this status. Delete the artifact as its own resolution rule requires, or stop claiming it was deleted.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Deleted in 01ed815 on schickling/hs-08-integration: the DELTA-005 file is actually removed (its resolution rule was met when the producers landed) and the Status paragraph now agrees with the tree.
Posted on behalf of @schickling
| field | value |
|---|---|
agent_identity |
unknown |
agent_persona |
generalist |
agent_supervisor |
unavailable |
agent_tool |
OMP |
agent_tool_version |
18.0.3 |
agent_runtime |
OMP 18.0.3 |
tooling_profile |
dotfiles@f33cd9c-dirty |
… now prove Scoped delivery-input wakeups and the observed-harness-state discipline (derived-only unknown, byte-distinct writes, evidence-gated heartbeat, terminal-before-escalation), per CLAUDE.md's green-test gate. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…scalation A real-wrapper subprocess proof: the wrapper runs as its own process group with a TERM-ignoring provider, st2's stop path escalates after STOP_GRACE, and the record reads ended/signal 9 — the clause the discipline row previously claimed without a covering test. The row's wording now also names the driver processes (wrapper, channel, hooks) per the multi-writer design, the restatement bound, and the new proofs. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The pi section states the channel/wrapper ownership split and the agent_settled idle edge with its why; reader-side limits gain the pty-kill pidfile removal and the codex >=0.148 pin refusal; DQ-H2 records the measured 3 Hz failure mode and its envelope fix; the ontology entry drops the reserved word 'working'. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
… installed trap The status file only proved the wrapper spawned the child; a slow scheduler could let SIGTERM kill the provider inside the grace window and pass the test without exercising escalation. The provider now writes a ready marker after trap '' TERM, and the signal waits for it. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Spec, requirements, and ontology align with cycle 2: the session-takeover write-through rule, ptySession required for live states (unfenced-record derivation), unreadable-record and unsupported-schema rows, the ask kind across the vocabulary and all four producer tables, stop-aware codex startup, question re-seeding on reconnect, and the probe root resolving exactly as the runner does. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…roducer rules The Draft rationale names the real residuals (DQ-H5 and the eventless deny window) now that both captures are folded in; the record contract states incarnation-token ownership and monotonic stamps; codex documents pending-retry evidence, pi its terminal-only observer, opencode its atomic seed and full gate subset, and claude union supersession, late-hook fencing, and the hooks-only limitation. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…the cycle-4 producer rules Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…mplementation Escalation writes the cover record before the group SIGKILL, a grace-window reap rewrites it with the real exit, and the discipline row's proof list names both — proven against the real wrapper binary. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ndow honestly Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…LL death A wrapper that exited any other way never exercised the escalation path; both stop-implementation escalation cases now pin the wrapper's exit signal. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…y-seat coverage, atomic seeds, degrade-not-die launches Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…tup waits, shape-gated seeds, silence horizons Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…projection Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…005 stays deleted The projection table gains the claimed row and both claim statements match the shipped reader: a fresh exitless superseded placeholder derives indeterminate (reason 'claimed') until the session's first real observation. The seed/poison guarantee now states the widened rule — any session's unreadable status word poisons, sticky terminals outrank it. The DELTA-005 file, whose resolution rule was met when the producers landed, is deleted so the status claim and the tree agree. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> agent-identity: unknown agent-persona: generalist agent-supervisor: unavailable agent-tool: OMP agent-tool-version: 18.0.3 agent-runtime: OMP 18.0.3 tooling-profile: dotfiles@f33cd9c-dirty
13944ab to
01ed815
Compare
Integration pass over the merged stack.
Docs↔code reconciliation: DQ-H1 and the spec's Claude section state the implemented blocked-exit rule — now measured-correct, not merely conservative: the 2026-08-23 batched-permission capture shows tool execution serializes around an open permission prompt, so the predicted false-clear cannot occur; the residual eventless-deny path is pinned in DQ-H1. DQ-H6 resolved by the live OpenCode capture. DQ-H2 resolved by measurement (the pre-fix 3 Hz write volume and the post-guard per-turn expectation).
DELTA-005 deleted per its own resolution rule: all seven landing boxes are checked by this stack, so the docs-ahead-of-code fence closes with the change that completes it.
INVARIANTS.md: the observed-harness-state rows cite their real proofs, including the subprocess teardown test — a real wrapper process with a TERM-ignoring provider is stopped, and the record reads
ended/signal 9before the group SIGKILL.Reader-side limits stated in the spec:
pty killremoves the pidfile (probe indeterminate until the horizon), and hosts on codex-cli ≥ 0.148 produce no Codex observed state until the version pin moves (st2 refuses the locally installed codex-cli, and the version pin is now behind by one release #267).Cycle-2: the teardown proof synchronizes on a ready marker the provider writes after installing its trap (deflaked — five consecutive green runs); spec, requirements, and ontology align with session-owned writes, fenced live records (
unfenced-record,unreadable-record,unsupported-schemaderivations), and the machine-readableaskaxis across all four producer tables.Cycle-3: the Draft rationale names the genuine residuals (DQ-H5, the eventless deny window) now that both captures are folded in; the contract states incarnation-token ownership, monotonic stamps, and the per-producer cycle-3 rules.
Cycle-4: the teardown matrix covers opencode's own stop implementation (escalation cover before SIGKILL; graceful reap rewrites with the real exit), the invariant row cites both, and the ownership-direction docs carry the record example and residuals.
Cycle-5: the dual-claim residual dissolved (written claims serialize on the lock); the pty-kill window is stated as genuinely open — bounded by the staleness horizon or the next relaunch claim — with the cross-check scoped to provably dead sessions and no fabricated death evidence.
Part of the #268 stack (#319→#326).
🤖 Generated with Claude Code